Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40885

27
FAUCET Score

OVERVIEW CVE-2026-40885 is a credential disclosure vulnerability affecting goshs, a lightweight HTTP server written in Go, specifically versions 2.0.0-beta.4 through 2.0.0-beta.5. The flaw allows unauthenticated attackers to capture file-based access control list credentials by monitoring the server's public collaborator feed when global basic authentication is not enabled. SEVERITY The vulnerability has a moderate risk profile with a FAUCET Risk Score of 39.0/100 and an EPSS score of 0.000680. The attack requires network access to the collaborator websocket but no authentication, and exploitability is straightforward once credentials are captured. The impact is significant: attackers can read, upload, overwrite, and delete files within protected directories by replaying captured Authorization headers, potentially leading to data theft, integrity compromise, and service disruption. EXPLOITATION STATUS There is currently no evidence of active exploitation in the wild, as the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog and is marked as inactive on threat lists. However, the technical simplicity of the attack vector—passive monitoring of websocket traffic—may allow exploitation to occur undetected. The vulnerability was patched in version 2.0.0-beta.6, and users should upgrade immediately.

Impacted Technologies

VendorProductVersion(s)CPE
2.0.0CPE matchmatch criteria
cpe:2.3:a:goshs:goshs:2.0.0:beta4:*:*:*:go:*:*
2.0.0CPE matchmatch criteria
cpe:2.3:a:goshs:goshs:2.0.0:beta5:*:*:*:go:*:*

CVSS Data

CVSS version used by this source: 4.0

7.7HIGH

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
PASSIVE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.31%
Probability of exploitation in next 30 days
EPSS Percentile
23.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0031 is in the 28th percentile among its peer group of 14,848 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

gopatch availablevia ghsa
Product: github.com/patrickhener/goshs/v2Fixed in: 2.0.0-beta.6
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

goGHSA-7h3j-592v-jcrphigh

goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access

Apr 14, 2026

References

github.com / patrickhener/goshs/security/advisories/GHSA-7h3j-592v-jcrp
ExploitVendor Advisory